Security
OWASP Top 10
A regularly updated, widely referenced list of the ten most critical web application security risks (like injection attacks and broken access control), published by the OWASP foundation.
Think of it like
Like a restaurant health inspector's standard checklist of the most common ways a kitchen actually makes people sick — a shared baseline everyone in the industry references.
Junior or senior?
Junior sounds like
Can recite the OWASP Top 10 list.
Senior sounds like
Can name a specific risk from it they've actually had to fix in production code, and what the fix was.
Ask them
“Which OWASP Top 10 risk have you actually had to fix in production code, and what was the fix?”